ZAST AI[verified]@zast_aiDisclosure
The tweet confirms the existence of CVE‑2026‑33419 in MinIO, detailing that the LDAP-backed STS flow improperly exposes usernames and hands out temporary credentials, constituting an authentication bypass.
ZAST AI[verified]@zast_aiGeneral
The post references a technical report on CVE-2026-33419 and a code analysis tool, but does not provide any PoC, exploit, active exploitation, patch, or detailed technical information.
CCB Alert@CCBalertDisclosure
The post warns about two critical CVEs affecting MinIO’s OIDC and LDAP authentication, notes that attackers could forge identities or brute‑force access, and indicates that patches are available.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑33419, detailing how MinIO’s STS endpoint leaks usernames and enables LDAP brute‑force, but it does not provide a PoC, exploit code, active exploitation evidence, or patch information.
PulsePatch.io@pulsepatchioDisclosure
CVE‑2026‑33419 exposes a MinIO LDAP brute‑force and enumeration flaw caused by missing rate limits, and the advisory recommends applying network‑level rate limiting to mitigate unauthorized access.